Director, Digital Audit, Inspection & Continuous Improvement
Pfizer
- Location
- United States New York New York City
- Work model
- On-Site
- Level
- Staff
- H-1B history
- 9 approvals (FY2023)
- Posted
- Sep 8, 2026
Skills
About this role
ROLE
SUMMARY Our Global Cybersecurity Governance, Risk Management, and Compliance (CGRC) team provides comprehensive blueprints for cybersecurity excellence by embedding governance, CGRC, and compliance into every layer. The team is responsible for ensuring risk-based decision-making is used and that security, privacy, regulatory compliance and continuous improvement is integrated seamlessly with Pfizer’s organization. The Director, Digital Audit, Inspection & Continuous Improvement role will be responsible for implementation and execution of the full range of CGRC services to Digital lines, partner with senior leaders of the organizations and engage with their leadership teams to develop and implement a comprehensive compliance strategy based on risk. The role will also serve as the point of accountability to ensure that appropriate proactive controls are established to manage risk and develop and implement remediation strategies to close any audit and inspection gaps. In addition, this role will serve as the champion for Creation Centers to ensure continuous improvement of global and division specific compliance processes and to ensure that the processes are efficient, straightforward and robust. This role supports audits and inspections directly and indirectly along with remediation actions and projects. This position has direct reports.
ROLE
RESPONSIBILITIES This role will have the following primary responsibilities: Provides guidance and direction aligned to existing or new developing strategies, regulations and technologies. Accountable for the development, management, execution, and strategy for ensuring technology compliance with or demonstration of controls to manage overall Regulatory Compliance and Pfizer Policy requirements (e.g., GxP, SOX, Privacy, Security, SDLC, etc.). Accountable for the development, implementation, and management of a repeatable Compliance strategy, solutions, services, and standards for initiatives within Digital and related technology areas supported by this role. Works to ensure all customer activities address Regulatory, Privacy, Quality Standards and Security Risks. Manages risks of activities with senior management acceptance as appropriate. Defines governance frameworks and operating models and drive organizational risk decisions. Accountable for Enterprise compliance outcomes and able to influence VP-level and executive stakeholders Leads transformation and capability development In coordination with internal CGRC operations and the Digital Line organizations, identify and implement Performance Indicators, metrics and standard reports to drive compliance improvements. Report routinely to Digital lines and Quality on the state of compliance. Provides CGRC consultancy and expertise to colleagues regarding regulatory compliance for technology solutions. Provides strategic and operational CGRC consultancy to support implementation of technology. Align CGRC strategies to the strategic direction and operational needs related to technology implementation. In support of the development and delivery of Digital services and Digital supported solutions, provide risk management direction, compliance event management, periodic review, inspection readiness, and all other CGRC activities as needed in accordance with the Digital Process Framework. Meet with respective Digital line leadership as presented in the CGRC engagement model; Attend program/project team meetings and engage with Senior Leadership in Digital, thebusiness lines, and external partners Manage customer demand for CGRC services and performance of managed service provider for assigned Digital lines as required. Drive the CGRC strategies to support the business model with internal and external processes. Partner with Digital lines in projects representing compliance controls and risk management practices to effectively provide visibility to risks and regulatory